NIST 800-53 Rev 5

424 controls available

CM-7(5)moderatehigh

Authorized Software — Allow-by-exception

Configuration Management

Control Statement

Identify {{ insert: param, cm-07.05_odp.01 }}; Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system; and Review and update the list of authorized software programs {{ insert: param, cm-07.05_odp.02 }}.

Discussion

Authorized software programs can be limited to specific versions or from a specific source. To facilitate a comprehensive authorized software process and increase the strength of protection for attacks that bypass application level authorized software, software programs may be decomposed into and monitored at different levels of detail. These levels include applications, application programming interfaces, application modules, scripts, system processes, system services, kernel functions, registries, drivers, and dynamic link libraries. The concept of permitting the execution of authorized software may also be applied to user actions, system ports and protocols, IP addresses/ranges, websites, and MAC addresses. Organizations consider verifying the integrity of authorized software programs using digital signatures, cryptographic checksums, or hash functions. Verification of authorized software can occur either prior to execution or at system startup. The identification of authorized URLs for websites is addressed in [CA-3(5)](#ca-3.5) and [SC-7](#sc-7).

Framework
NIST SP 800-53 Rev 5
Family
Configuration Management
Baselines
moderate, high

Related Frameworks

8 paths across 2 frameworks
NIST 800-1711 mapping
3.4.8
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI7 mappings
CCI-001772
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001773
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001774
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001775
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001776
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001777
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001778
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

414 STIGs reach this control through 40 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

8 STIGs

Operating System — Server

44 STIGs
IBM AIX 7.x Security Technical Implementation Guide
V3R22026-02-0649 of 283 findings match
IBM AIX 7.x Security Technical Implementation Guide
32024-08-1649 of 283 findings match
Show 36 more STIGs in this category →
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-1745 of 448 findings match
Oracle Linux 8 Security Technical Implementation Guide
V2R82026-02-1330 of 375 findings match
Amazon Linux 2023 Security Technical Implementation Guide
V1R32026-02-2710 of 187 findings match
Solaris 11 X86 Security Technical Implementation Guide
V3R52026-02-192 of 216 findings match

Operating System — Mainframe

69 STIGs
IBM z/OS ACF2 Security Technical Implementation Guide
V9R82026-03-0915 of 225 findings match
IBM z/OS TSS Security Technical Implementation Guide
92025-06-2414 of 231 findings match
IBM z/OS RACF Security Technical Implementation Guide
V9R82026-03-0913 of 222 findings match
IBM z/OS TSS Security Technical Implementation Guide
V9R82026-03-0913 of 230 findings match
CA IDMS Security Technical Implementation Guide
V2R12024-09-135 of 74 findings match
Show 61 more STIGs in this category →
Mainframe Product Security Requirements Guide
V3R42025-09-101 of 194 findings match
Mainframe Product Security Requirements Guide
32024-12-051 of 193 findings match

Operating System — Mobile

40 STIGs
Show 32 more STIGs in this category →

Network Device

97 STIGs
AAA Services Security Requirements Guide
V2R22024-12-044 of 77 findings match
Show 89 more STIGs in this category →
Application Layer Gateway Security Requirements Guide
V2R32025-09-153 of 160 findings match
Cisco ACI NDM Security Technical Implementation Guide
V1R22025-12-112 of 26 findings match
Cisco ISE NDM Security Technical Implementation Guide
V2R32025-12-112 of 53 findings match
Domain Name System (DNS) Security Requirements Guide
V4R22025-12-192 of 119 findings match
F5 NGINX Security Technical Implementation Guide
V1R12026-01-072 of 32 findings match
BIND 9.x Security Technical Implementation Guide
V3R22026-02-251 of 73 findings match
BIND 9.x Security Technical Implementation Guide
22024-02-151 of 70 findings match
Cisco ASA NDM Security Technical Implementation Guide
V2R42025-12-081 of 47 findings match
Cisco ASA VPN Security Technical Implementation Guide
V2R22024-08-221 of 41 findings match
Firewall Security Requirements Guide
V3R32025-09-221 of 35 findings match
Firewall Security Requirements Guide
32024-12-041 of 34 findings match
Layer 2 Switch Security Requirements Guide
V3R42026-02-121 of 36 findings match
Layer 2 Switch Security Requirements Guide
32025-03-051 of 28 findings match
Network Device Management Security Requirements Guide
V5R32025-02-111 of 104 findings match
Network Device Management Security Requirements Guide
V5R42025-09-101 of 105 findings match
Router Security Requirements Guide
V5R22025-09-101 of 123 findings match
Router Security Requirements Guide
52024-05-281 of 108 findings match
RUCKUS ICX NDM Security Technical Implementation Guide
V1R12025-05-281 of 25 findings match
SDN Controller Security Requirements Guide
22024-05-281 of 34 findings match
SEL-2740S L2S Security Technical Implementation Guide
V1R12019-05-061 of 13 findings match

Database

25 STIGs
Database Security Requirements Guide
V4R52026-02-266 of 142 findings match
Show 17 more STIGs in this category →
Database Security Requirements Guide
42024-12-046 of 142 findings match

Web / Application Server

33 STIGs
Web Server Security Requirements Guide
V4R42025-09-1014 of 126 findings match
Web Server Security Requirements Guide
42025-02-1214 of 124 findings match
Show 25 more STIGs in this category →
Application Server Security Requirements Guide
V4R42025-09-102 of 137 findings match
Application Server Security Requirements Guide
42025-02-112 of 128 findings match

Virtualization / Container

46 STIGs
Show 38 more STIGs in this category →
Container Platform Security Requirements Guide
V2R42025-09-108 of 188 findings match
Container Platform Security Requirements Guide
22025-05-158 of 187 findings match
Kubernetes Security Technical Implementation Guide
V2R62026-02-126 of 92 findings match
Virtual Machine Manager Security Requirements Guide
22024-12-066 of 193 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-106 of 198 findings match

Endpoint Security Management

27 STIGs
Tanium 7.x Security Technical Implementation Guide
V2R32025-05-1410 of 98 findings match
BlackBerry UEM Security Technical Implementation Guide
V2R12020-12-044 of 16 findings match
ISEC7 Sphere Security Technical Implementation Guide
V3R12024-08-204 of 34 findings match
Show 19 more STIGs in this category →
Central Log Server Security Requirements Guide
V3R42026-02-121 of 127 findings match
Central Log Server Security Requirements Guide
32024-12-041 of 125 findings match
HYCU Protege Security Technical Implementation Guide
V1R22026-03-041 of 55 findings match

Productivity Application

14 STIGs
Microsoft Edge Security Technical Implementation Guide
V2R52026-02-2549 of 61 findings match
Mozilla Firefox Security Technical Implementation Guide
V6R72025-11-2527 of 34 findings match
Show 6 more STIGs in this category →

Uncategorized

11 STIGs